Ransomware Attack on Ryder Scott Co. by Play Ransomware Group

Incident Date:

May 22, 2024

World map

Overview

Title

Ransomware Attack on Ryder Scott Co. by Play Ransomware Group

Victim

Ryder Scott Co.

Attacker

Play

Location

Houston, USA

Texas, USA

First Reported

May 22, 2024

Ransomware Attack on Ryder Scott Co. by Play Ransomware Group

Victim Overview

Ryder Scott Company, a petroleum consulting firm based in Houston, Texas, was targeted by the cybercrime group Play in a ransomware attack. The company independently estimates oil and gas reserves, future production profiles, and cashflow economics, providing expert guidance to clients in the oil and gas industry.

Company Profile

Ryder Scott has 109 employees in the U.S. and has been in business since 1937, showcasing a substantial presence in the petroleum consulting industry. The company stands out for its commitment to professionalism, integrity, and quality service, aiming to be the preferred oil and gas engineering and geological consultants worldwide.

Attack Details

The attackers exfiltrated sensitive data from Ryder Scott, including private and personal confidential information, client documents, budgets, payroll records, accounting data, contracts, tax information, IDs, and financial data. This data was subsequently leaked by the threat actors, highlighting the severity of the attack.

Ransomware Group Profile

The Play ransomware group, operated by Ransom House, is known for targeting Linux systems and has evolved to deploy cryptographic lockers. The group distinguishes itself with a unique approach to victim communication and shares code similarities with other Babuk variants, showcasing a sophisticated evolution in ransomware tactics.

Attack Penetration

Play ransomware actors have been observed submitting binaries containing hack tools and utilities associated with ransomware techniques after achieving initial access to Ryder Scott's systems. The group's focus on Linux environments and its adoption of cryptographic lockers may have enabled them to penetrate the company's defenses.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.